Home
MEDIUM: 4.4 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NDefault status
affected
vers:all/* (custom)
affected
Description
The VNC application stores its passwords encrypted within the registry but uses DES for encryption. As DES is broken, the original passwords can be recovered.
Problem types
CWE-257 Storing Passwords in a Recoverable Format
Product status
vers:all/* (custom)
References
www.cisa.gov/...es-tools/resources/ics-recommended-practices
www.first.org/cvss/calculator/3.1
www.sick.com/.well-known/csaf/white/2025/sca-2025-0008.json
sick.com/psirt
www.sick.com/.well-known/csaf/white/2025/sca-2025-0008.pdf